Data Processing Addendum

Last updated: September 1, 2026

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer", the controller) and Turners OÜ ("Veyramesh", the processor). It applies where Veyramesh processes personal data on the Customer's behalf — in particular when the Veyramesh bot performs moderation, XP, verification, ticketing, and welcome flows in a Discord or Telegram server the Customer controls.

For clarity, Veyramesh acts as an independent controller (not a processor) for a limited set of platform-wide security functions described in the Privacy Policy (for example detecting a bad actor across multiple servers). Those activities are outside this DPA.

2. Subject-matter and details of processing

  • Subject-matter: provision of the Veyramesh bot and dashboard features the Customer enables.
  • Duration: for as long as the Customer uses the service, plus the retention periods in §8.
  • Nature and purpose: community moderation, engagement (XP/levels), verification, support ticketing, welcome flows, and related analytics and AI-assisted features, as configured by the Customer.
  • Categories of data subjects: members of the Customer's Discord/Telegram community.
  • Categories of personal data: platform user ID, display name, avatar, activity and join timestamps, XP/level, moderation actions, ticket contents, verification status, and — where the Customer enables it — sentiment analysis of messages.
  • Special category data: not intentionally processed. The Customer must not configure the service to process special-category data.

3. Veyramesh's obligations

Veyramesh will:

  • process personal data only on the Customer's documented instructions (including the configuration choices the Customer makes in the dashboard), and as required by applicable law;
  • ensure people authorized to process the data are under an obligation of confidentiality;
  • implement appropriate technical and organizational security measures (§6);
  • respect the conditions for engaging subprocessors (§4);
  • assist the Customer, taking into account the nature of the processing, in responding to data-subject requests (§5);
  • assist the Customer with security, breach notification, DPIAs, and prior consultation, taking into account the information available to Veyramesh;
  • at the Customer's choice, delete or return the personal data at the end of the service, and delete existing copies unless law requires retention;
  • make available information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates (subject to reasonable confidentiality and scheduling).

4. Subprocessors

The Customer gives general authorization for Veyramesh to engage subprocessors. The current list is published at /subprocessors. Veyramesh will inform the Customer of any intended addition or replacement of a subprocessor with a reasonable period's notice, giving the Customer the opportunity to object on reasonable data-protection grounds. Veyramesh imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA and remains liable for its subprocessors' performance.

5. Data-subject requests

Taking into account the nature of the processing, Veyramesh will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a data subject contacts Veyramesh directly about data processed under this DPA, Veyramesh will (unless legally prohibited) direct them to the Customer or promptly forward the request.

6. Security

Veyramesh maintains measures appropriate to the risk, including: encryption of access tokens and secrets at rest; organization-scoped access controls; role-based access within a workspace; logging of privileged staff access to customer data; secure software-development and dependency-management practices; and regular security review. A summary of the current security posture is available on request.

7. Personal data breach

Veyramesh will notify the Customer without undue delay after becoming aware of a personal data breach affecting data processed under this DPA, and will provide the information the Customer reasonably needs to meet its own notification obligations.

8. Retention and deletion

Personal data is retained in line with the Customer's configuration and the retention periods Veyramesh applies (moderation and ticket data generally kept while the bot is installed and for a limited period afterwards; security signals and AI outputs on a rolling basis of up to 12 months). On termination, or on the Customer's written request, Veyramesh will delete or return the personal data, subject to legal retention requirements. Deletion propagates to backups within Veyramesh's backup rotation period.

9. International transfers

Veyramesh's database and file storage are in the EU. Where personal data processed under this DPA is transferred to a subprocessor outside the EEA/UK, Veyramesh relies on an appropriate transfer mechanism (principally the EU Standard Contractual Clauses), details of which are available on request. The EU Standard Contractual Clauses are incorporated by reference where they apply, with Veyramesh as data importer or, as applicable, as the Customer's processor exporting to a sub-processor.

10. General

This DPA is governed by the same law as the Terms of Service. In the event of a conflict between this DPA and the Terms on the subject of personal-data processing, this DPA prevails. If any provision of the applicable Standard Contractual Clauses conflicts with this DPA, the Standard Contractual Clauses prevail.

11. Contact

support@veyramesh.com — Turners OÜ, Jõe tn 3-406, Kesklinna linnaosa, Tallinn, Harju maakond, 10151, Estonia.